Talk With an Expert

Monitoring The ARP Protocol On Local Area Networks

Monitoring The ARP Protocol On Local Area Networks (PDF, 2.10MB)Published: 11 Jan, 2004
Created by
David Fuselier

This practical assignment is a research paper on how to use the ARP protocol to monitor local area networks. The ARP protocol can be used to take an inventory of computers on the network, alert when new machines are connected, inspect ARP traffic for computers that are scanning the network, and if you record the ARP traffic, it can provide a tool to help clean up after worm attacks and provide a record of communications to explain other events. The practical begins with a description of the ARP protocol, packet formats, and characteristics of the protocol. The next section contains a survey of different ARP monitoring programs that are available such as arpwatch7 and tcpdump. The last section talks about monitoring wireless networks. The same principles for monitoring wired networks apply to wireless if you can get windump to show ARP traffic on your wireless computer. These tools by no means provide comprehensive network security. It would be possible to conceal a computer from the ARP monitoring by not broadcasting ARP packets.

Monitoring The ARP Protocol On Local Area Networks